01Who we are and what this policy covers
DBA AML Group Pty Ltd (ABN [ABN]) (DBA AML, we, us), a division of DBA Advisory, provides a regulatory client onboarding, compliance and lifecycle management platform (the Platform) and related compliance services, including outsourced AML/CTF compliance officer services, to Australian businesses regulated under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
This Privacy Policy explains how we collect, hold, use and disclose personal information, and how you can access and correct it or make a complaint. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we take those obligations seriously — privacy discipline is, after all, our trade.
This policy covers our website (dbaaml.com), the Platform (including its authentication service at auth.dbaaml.com), and our compliance services.
02The two capacities in which we handle information
Understanding this policy starts with a distinction:
- Information we collect for ourselves — about visitors to our website, our subscribers and their staff, and people who contact us. We decide how and why this is handled.
- Information processed on behalf of our subscribers — our subscribers are reporting entities who use the Platform to meet their own customer due diligence obligations. The information they enter about their clients (including identity documents and verification results) is collected by them for their compliance purposes; we process it on their behalf, on their instructions and under strict confidentiality. If you are the client of one of our subscribers, that subscriber is your first point of contact for privacy questions, and their privacy policy applies alongside this one.
03What we collect
Account and contact information
- Name, email address, phone number, role and organisation of subscribers, their personnel and enquirers;
- sign-in identifiers managed through our authentication provider, including where you choose to sign in with a Google or Microsoft account (we receive your name, email address and profile identifier from that provider — never your password);
- billing details and transaction history for subscriptions and usage.
Compliance-file information (processed for subscribers)
- Identity information about subscribers’ clients and their related parties: names, dates of birth, addresses, identity document details and images;
- biometric information collected during electronic identity verification — a facial image and liveness data used to match a person to their identity document (see section 4);
- company, trust, partnership and beneficial-ownership information, including public-register data;
- screening results against politically-exposed-person, sanctions and adverse-media data sources, and the decisions recorded on them;
- matter, transaction and reporting records the subscriber creates in the course of its compliance program;
- training completions, assessment results and certificates for subscriber personnel.
Technical and usage information
- Device, browser and log data, IP addresses, pages visited and actions performed (the Platform keeps a comprehensive audit trail — that is a feature, and it necessarily records who did what, when);
- cookies and similar technologies (section 11).
04Biometric and identity-verification information
Electronic identity verification on the Platform can include document checks, facial matching and liveness detection. Biometric information is sensitive information under the Privacy Act, and we treat it accordingly:
- it is collected only with the consent of the individual being verified, obtained at the point of verification;
- it is used solely to verify that individual’s identity for the requesting subscriber’s AML/CTF purposes — never for marketing, profiling or any unrelated purpose;
- it is processed through specialist, security-vetted identity-verification providers, and handled under contractual safeguards;
- verification may also involve checks against official document-issuer and registry sources, and can be conducted to standards required for property transactions (including the ARNECC verification-of-identity framework).
05Why we collect it and the lawful bases
| Purpose | Basis |
|---|---|
| Providing, securing and supporting the Platform and our services | Performance of our agreement with the subscriber |
| Enabling subscribers to meet customer identification, verification, screening, record-keeping and reporting obligations | The subscriber’s legal obligations under the AML/CTF Act and Rules |
| Biometric identity verification | Consent of the individual, obtained at the point of verification |
| Billing, account administration and communications | Performance of our agreement; legitimate operation of our business |
| Complying with our own legal obligations, including to regulators | Required or authorised by law |
| Improving the Platform (on de-identified or aggregated information wherever practicable) | Legitimate operation of our business |
We do not sell personal information. We do not use client-file information for advertising, and we do not use biometric information to train models.
06Who we disclose information to
We disclose personal information only as needed to run the Platform and our services, on a need-to-know basis and under contractual confidentiality:
- Specialist verification and screening providers — to perform electronic identity verification, business-register (KYB) checks and PEP, sanctions and adverse-media screening;
- Infrastructure providers — secure cloud hosting, database and storage services on which the Platform runs;
- Authentication provider — to operate secure sign-in, including social sign-in with Google or Microsoft where you choose it;
- Communications and billing providers — transactional email delivery and payment processing;
- Regulators and authorities — AUSTRAC and other bodies where disclosure is required or authorised by law;
- Professional advisers — lawyers, accountants and insurers under duties of confidence;
- Our subscribers — the information their own users enter, and verification and screening results relating to their clients, is available to them as the controllers of that information.
07Overseas disclosures
Some of our service providers (including cloud infrastructure, verification, screening and authentication providers) may store or process information outside Australia, including in the United States and other jurisdictions in which they operate. Where that occurs, we take reasonable steps — including contractual measures — to ensure the information is handled consistently with the APPs. Compliance records created on the Platform are retained under Australian law regardless of where the underlying infrastructure sits.
08How long we keep information
Retention on this Platform is largely dictated by statute. The AML/CTF Act requires reporting entities to retain customer identification and transaction records for seven years (generally from the end of the customer relationship or the making of the record). Records created on the Platform for a subscriber’s compliance program are therefore retained for at least that period, even after a client relationship or a subscription ends, unless the subscriber lawfully takes custody of them.
Information not subject to statutory retention (for example, marketing enquiries) is kept only as long as needed for the purpose it was collected, then deleted or de-identified.
09Legal limits on what we can tell you
10How we protect information
- Encryption in transit; hardened, access-controlled infrastructure;
- authentication through a dedicated enterprise identity provider, with authorisation enforced in the Platform’s own database;
- strict tenant isolation — each subscriber’s data is scoped to its own account;
- comprehensive audit logging of material actions;
- staff access on a need-to-know basis, under confidentiality obligations;
- vendor due diligence and contractual safeguards for every processor listed in section 6.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
11Access, correction and your choices
You may request access to, or correction of, personal information we hold about you by contacting us (section 13). We respond within a reasonable period, verify your identity before acting, and if we refuse a request (for example, where the law requires it — see section 8) we will tell you why to the extent we lawfully can, and how to complain.
If your information sits in a subscriber’s compliance file, we will refer your request to that subscriber, whose obligations and instructions govern that file. You can also opt out of any non-essential communications at any time; service and security notices are part of operating the Platform and cannot be opted out of while you hold an account.
12Cookies and website analytics
The website and Platform use cookies that are necessary for sign-in, security and session integrity. These are essential and cannot be disabled while using the Platform. Any analytics we use on the public website are configured for aggregate understanding of usage, not the profiling of individuals. You can control cookies through your browser; blocking essential cookies will prevent sign-in.
13Complaints
If you believe we have mishandled your personal information, contact us first (section 13) — we will acknowledge your complaint promptly, investigate, and respond within 30 days. If you are not satisfied with our response, you may complain to the OAIC at oaic.gov.au or 1300 363 992.
14Contacting us and changes to this policy
Privacy Officer
DBA AML Group Pty Ltd (a division of DBA Advisory)
Email: privacy@dbaaml.com
Address: G01/38A Cumberland St, The Rocks NSW 2000
We may update this policy from time to time. The current version is always at dbaaml.com/privacy.html, with its effective date shown at the top. Material changes affecting subscribers will be notified through the Platform.